Live data from Hacker News

You don’t want to be on Cloudflare’s naughty list

ctrl.blog

61–70 of 354 posts

Re: You don’t want to be on Cloudflare’s naughty list

#61

Earlier quoted context omitted.

I completely agree. I am against Cloudflare and the centralization it implies 100%. I never use it for sites I develop. I just have no sympathy for Daniel since up until just now he was trying to get everyone to do this.

CloudFlare allows website host to have much finer grain control that would have solved many of these problems - if they pay for it . I see no problem with this.

The hosts aren't blocking him though, it's Cloudflare.

> Just about every website I visited from my home internet connection would result in a challenge page.

Re: You don’t want to be on Cloudflare’s naughty list

#62
post #38
post #3

Well into the second day of Cloudflare’s blockade of my home internet connection, Google Search also began blocking requests. It required me to resolve a CAPTCHA challenge for every other search. This luckily only lasted a day. Cloudflare shares IP reputation data with partners like Google, coordinated through a program called the Bandwidth Alliance. So, my original offense might not even have been against Cloudflare…

FYI, this guy is far from alone, your "protection" has given me a lot of grief over the past few years, particularly on highly NATed mobile networks. I've been gradually removing cloudflare based CDNs from services I develop and control because I don't want my users being arbitrarily discriminated against. There was a good article posted on HN recently titled "The ideal level of fraud is non-zero" which I think is hi…

Cloudflare just isn't worth the tradeoffs: the risks associated with their centralization, how they made Tor basically unusable on non-onion sites, the lack of transparency when content-moderating the internet, etc.

The space is in need of solid competitors to break the stranglehold they have on the internet. Whether it's the right combination of services, documentation, etc.

Re: You don’t want to be on Cloudflare’s naughty list

#63
Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying.

A few months ago I got on Akamai's naughty list (with my other ISP) for some very light automated website downloading. That was a straight block with HTTP errors and I had to use a proxy to access the Web. It cleared up after a few days.

The lack of any user feedback or support for this situation is really annoying. Reminds you how much power the CDNs have. It'd be really bad if loading websites got as difficult as sending email through all the layers of spam filtering.

Re: You don’t want to be on Cloudflare’s naughty list

#64

Has he tried unplugging the router for 15 minutes and plugging it back in? I jest but I know Comcast and Spectrum will both issue a new IP address in that timeframe.

IP bans by modern services like CF can't be solved that easily in my experience.

Re: You don’t want to be on Cloudflare’s naughty list

#66
If you'd like to experience this treatment first-hand, try surfing the web using the Tor Browser.

Spoiler alert: many websites simply refuse to load at all (e.g. any google service, and lots of websites "protected" by CF). Captchas are everywhere: in many cases, you can't even complete simple GETs of blogs without donating free labor to CF.

And the most infuriating part, you get CF marketing messages right in your face while your browser is calculating hashcash (I guess?)... At this point I can recognize every single one of them: something about bots making up 40% of all internet traffic, something about their web scraper protection racket, something about small businesses (???), etc etc...

To be fair, Tor exit nodes have an awful reputation for sure. Nevertheless, I have a hard time forgiving how CF makes browsing the Internet hell for those who actually need Tor.

Re: You don’t want to be on Cloudflare’s naughty list

#67
I have two dedicated home internet IPs (one iCable fibre and a China Mobile 5G fallback/quarantine WiFi) and get these "checking if your internet connection is secure" interstitials all the time now. Also see them on my HKBN work connection.

I'm from Hong Kong and suspect the whole territory is on the naughty list.

Re: You don’t want to be on Cloudflare’s naughty list

#68

Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying. A few months ago I got on Akamai's naughty list (with my other ISP) for some very light automated website downloading. That…

But any automated tool won't work. I have a similar problem with my self hosted feed reader, my vps hosting ip doesn't have 100% reputation with Cloudflare and I can't download some feeds

Edit: spelling

Re: You don’t want to be on Cloudflare’s naughty list

#69
post #60

Is it plausible some ISP shared some IP address that was on Cloudflare's list of suspicious IPs, or that some IoT device on this person's network created a burst of suspicious traffic? I get that this sucks for the end user, but I wonder how much we should blame Cloudflare vs the wider systemic challenges of managing DDOS protection on the web.

I believe that might happen, but then I also believe it's the ISP's responsibility to ensure that its IP addresses are kept clean

For sure, the point I'm making is that there's a multi party transaction here, with systemic complexity. Makes it hard to pin responsibility on just Cloudflare (or just the user or just the ISP, etc).

Re: You don’t want to be on Cloudflare’s naughty list

#70

There is a chance you might’ve been hacked. You would be surprised to see how easy it is to hack domestic routers. 1. Find and disinfect the devices, including the router. If you don’t have enough technical knowledge, then buy a new router. 2. Use 30 character long random password on the router. 3. Disable UPnP. 4. Anything with WI-FI and weak password can be hacked within minutes, so check your other devices as well…

Why would you disable UPnP? You're gonna break most collaboration tools/video games/etc.
Post reply on HN